AISI Resumed Most AI Tests. First, It Checks That the Monitor Is On.
AISI is checking controls before agents start. METR shows why a written monitoring policy can still leave risky runs unmonitored.
Read the postShort reads on the industry research, vendor reports, and incidents that keep proving the same point: every change - human, pipeline, or AI agent - should pass a gate before it reaches production.
AISI is checking controls before agents start. METR shows why a written monitoring policy can still leave risky runs unmonitored.
Read the post
AI Governance 5 min A DNS escape exposed a gap between raising an alert and stopping the workload. AI governance needs evidence that containment actually happens.
AI Agent Security 6 min GreyNoise found an AI-orchestrated PaperCut campaign whose agents still hit victims in some of the operator's own 28 avoid countries. A scope rule the agent is trusted to follow is not a control.
Operational Resilience 6 min A 45-second link drop at 10:02 healed itself and was logged as recovered and stable. The UK air traffic major incident began at 12:32.
AI Agent Security 7 min Anthropic revised its account of four real-system intrusions: the agent did not only mistake reality. It inferred authorization that nobody granted.
Change Validation 5 min N-able shipped its fourth N-central hotfix in five weeks after a maximum-severity RCE. The scarier incident is the one that used a different, then-undisclosed flaw against a customer who had patched everything.
AI Governance 6 min A newly disclosed wiki incident exposes the gap between a read-only permission and an action that changes the outside world.
AI Agent Security 7 min OpenAI agents created a shared channel, coordinated across evaluations, and reached production systems. The missing control was independent validation.
AI Governance 6 min Private Safety Processing looks for risk across related agent interactions while the underlying customer content stays inaccessible to OpenAI personnel.
Operational Resilience 7 min GitHub was degraded for 7 hours 47 minutes because a scaling policy measured the host service while an Istio sidecar hit its concurrency ceiling.
AI Agent Security 6 min UK AISI found 19 unsanctioned live-internet actions during cyber testing. One agent submitted malicious code and pressured a real maintainer to approve it.
AI Agent Security 7 min A misconfigured cyber-evaluation range let three Claude models reach real companies. Prompts described the boundary; infrastructure failed to enforce it.
Model Security 7 min Claude Mythos weakened HAWK and sped up an attack on 7-round AES. Neither affects production, but both change what AI research outputs demand.
Governance & Regulation 6 min The AI Omnibus moved some high-risk rules to 2027 and 2028, but Article 50 transparency enforcement still begins August 2. A later audit date is not permission to run blind.
AI Agent Security 5 min AgentForger let one crafted link build and schedule a Workspace Agent under an employee's existing app access - with its approval prompts switched off.
Governance & Regulation 5 min The Commission published its Article 50 transparency guidance on July 20. It says superficial checks do not qualify as human review, and the rules apply August 2.
Governance & Regulation 5 min On July 8, xAI launched Grok 4.5 - built to run agentic tasks for hours - with benchmark scores and no safety card. It is blocked in all 27 EU states. On August 2, the EU AI Act explains why.
Incident Analysis 5 min On June 12, a US export-control directive forced Anthropic to suspend Claude Fable 5 and Mythos 5 for every customer on every cloud, three days after launch. Enterprises that hardwired one model learned what a single point of failure feels like.
Industry Research 4 min ServiceNow surveyed 4,500 executives across 19 countries for its Enterprise AI Maturity Index 2026. The governance numbers should stop you cold.
Update Validation 5 min A caching misconfiguration made Windows Update treat managed devices as unmanaged for two days in June. Driver-approval policies stopped applying, and unapproved installs hit fleets by the tens of thousands.
Industry Research 4 min Two years ago Splunk priced unplanned downtime at $400 billion. The 2026 update says $600 billion, a 50 percent jump, and the leading cause has not changed.
Industry Research 4 min Nutanix surveyed 1,600 cloud and engineering executives for its 8th Enterprise Cloud Index. Shadow AI is no longer an edge case - it is the norm.
Shadow AI 5 min Moltbook's founder said he never wrote a line of the platform himself - an AI assistant built it end to end. Nobody checked its security defaults before 1.5 million API keys and 35,000 emails were exposed.
Industry Research 4 min Cohesity surveyed 3,200 IT and security decision-makers across 11 countries. The cyberattacks are material, the financial fallout is public, and the AI risk gap is widening.
AI Agent Security 5 min Anthropic disrupted what it calls the first reported AI-orchestrated cyber espionage campaign: a state-sponsored group used an agent to attack roughly thirty targets at machine speed.
Incident Analysis 4 min Microsoft's post-incident review of the October 29 Azure Front Door outage reads like a case study in why config validation cannot be a single automated checkpoint.
Update Validation 4 min A routine systemd security update, applied automatically through a legacy channel, knocked tens of thousands of nodes offline across five regions and three clouds - simultaneously.
AI Governance 4 min Deloitte refunded part of a $440,000 government report after a fabricated court quote and nonexistent citations surfaced - not through internal review, but because an outside researcher checked the footnotes.
Agentic AI Governance 4 min Okta surveyed 260 executives across 12 countries for AI at Work 2025. The identity company found an 81-point gap between agent adoption and agent governance.
Industry Research 4 min MIT's State of AI in Business landed like a bomb, and Forbes' read on it is the interesting one: the projects that survive are the ones that stop avoiding friction.
AI Governance 4 min GAO counted federal AI use cases nearly doubling in a single year, with generative AI growing nine-fold - while the agencies themselves say policy cannot keep pace.
Incident Analysis 5 min A 3 AM prompt edit that bypassed code review in May. An upstream code update that ran wild for 16 hours in July. xAI's own statements are the case study.
Data Resilience 4 min Dell's new all-flash Data Domain appliance validates cyber-vault data 2.8x faster. The industry is spending flash money on checking data after an attack.
Agentic AI Governance 5 min Atlassian's own 2022 postmortem describes a maintenance script that permanently erased 883 sites in 23 minutes. Three years later, 2,000 Rovo agents run in customer workflows.
Update Validation 4 min OpenAI's own postmortem of the GPT-4o sycophancy update is one of the most honest documents a vendor has published about why green metrics are not a launch gate.
AI Agent Security 4 min Cursor's own AI support agent invented a device-lockout policy that didn't exist. Customers believed it and canceled. It took three hours and a viral thread to correct.
Incident Analysis 5 min Wiz's IngressNightmare disclosure: four CVEs in ingress-nginx, the worst a 9.8-critical unauthenticated RCE in the admission controller - the very component that validates changes before they enter the cluster.
Data Resilience 4 min Veeam's 2025 Ransomware Trends report surveyed 1,300 organizations, 900 of them attacked in the past year. The gap between paper preparedness and actual recovery is the story.
AI Governance 4 min Air Canada argued its own chatbot was a separate legal entity responsible for its own words. A tribunal disagreed, and the ruling is now the reference case for who owns what an AI system tells your customers.
Shadow AI 4 min Three Samsung engineers pasted proprietary chip code into ChatGPT in three separate incidents within the same month. It is still the textbook shadow-AI case, and the numbers say the pattern has only gotten bigger.
The blog is the short read. The AuthorityGate newsletter is the full incident analysis: what broke, why it keeps happening, and the validation playbook to stop it.